CVE-2026-91025
Booking Manager < 2.1.21 - Subscriber+ Arbitrary User Plugin Meta Modification via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking Manager WordPress plugin before 2.1.21's per-user settings on arbitrary users, including administrators.
| Vendor | unknown |
| Product | booking manager |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown booking manager
Be the first to know when new unknown vulnerabilities affecting unknown booking manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Booking Manager
0 < 2.1.21
References
Credits
Choriyev Qahramon (ciprobe) WPScan